feat(phase-4a): groups sync + X-Project-Key header substrate
Foundational work for the upcoming group-scoped sharing feature.
Schema (migration 0003_groups.sql + drizzle schema):
- memory_access enum ('ro' | 'rw') reserved for Agent B's project_shares
- groups (id, oidc_iss, name, display_name, …) keyed by (oidc_iss, name)
so different IdPs can both have e.g. "platform" without colliding
- user_groups (user_id, group_id, synced_at) PK (user_id, group_id)
Auth (auth.ts + lib/auth/sync-groups.ts):
- jwt callback now syncs `profile.groups` after upserting the user
- syncUserGroupsFromClaim runs in a single tx: upserts each group,
inserts new memberships, deletes ones no longer in the claim
- missing/empty claim → user has zero groups (wipe memberships)
- EntraID GUID-vs-name edge case: we treat whatever strings the claim
emits as names verbatim; groups overage (>200 groups → no claim)
is documented as unsupported in v1
UserContext + JWT (lib/mcp/context.ts, lib/auth/jwt.ts):
- AuthenticatedClaims.groups surfaced from verified JWT payload
- UserContext.groups: string[] — live from OIDC token claim, falls
back to DB snapshot for CLI (HMAC) tokens which carry no claim
- UserContext.defaultProjectKey: optional, set from header
MCP route (app/api/mcp/route.ts):
- reads X-Project-Key header, validates against ProjectKey Zod schema,
400 on invalid; empty/missing leaves defaultProjectKey undefined
- auto-upserts the header-supplied project so first-use works without
a separate project.identify call
Tools (lib/mcp/tools.ts):
- withDefaultProject helper injects ctx.defaultProjectKey when the
caller omits `project`. Per-tool defaultScope hint avoids breaking
snippet.put (user-scope default) while making memory.write
(project-scope default) honor the header
- applied to memory.write/list/search/update and all snippet.* tools
Web UI:
- /settings/groups debug page lists current memberships with synced_at
and a clear empty state pointing at README troubleshooting
- /settings/tokens grows a "Pin to project" dropdown; selected key is
baked into the generated `claude mcp add` snippet as
`--header "X-Project-Key: <key>"`. The JWT itself stays
identity-only — pinning is purely a UX shortcut
- settings landing page links to /settings/groups
- README troubleshooting bullet covers the empty-groups path for
Authentik / EntraID / Keycloak
Refactor:
- extracted resolveProjectId + upsertProject from memory-actions.ts
into lib/projects.ts so the MCP route can reuse upsertProject
Verification:
- pnpm typecheck clean
- SKIP_ENV_VALIDATION=true pnpm build clean; /settings/groups in route table
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -0,0 +1,80 @@
|
||||
import Link from "next/link";
|
||||
import { eq } from "drizzle-orm";
|
||||
import { auth } from "@/auth";
|
||||
import { db } from "@/lib/db/client";
|
||||
import { groups, userGroups } from "@/lib/db/schema";
|
||||
import { Container, PageHeader } from "@/app/_components/ui/container";
|
||||
import { Card } from "@/app/_components/ui/card";
|
||||
import { EmptyState } from "@/app/_components/ui/empty-state";
|
||||
|
||||
export const dynamic = "force-dynamic";
|
||||
|
||||
/**
|
||||
* Debug page showing the OIDC groups currently associated with the signed-in
|
||||
* user. The list is rewritten on every sign-in from the IdP's `groups`
|
||||
* claim (see `lib/auth/sync-groups.ts`), so this view is effectively a
|
||||
* snapshot of "what your IdP told us about you at last login".
|
||||
*
|
||||
* Mainly intended as a sanity check for the upcoming sharing feature —
|
||||
* if the user expects to see "platform" and doesn't, the IdP probably
|
||||
* isn't emitting the claim, and the empty state points them at the
|
||||
* README troubleshooting section.
|
||||
*/
|
||||
export default async function GroupsSettingsPage() {
|
||||
const session = await auth();
|
||||
const userId = session!.user.id;
|
||||
|
||||
const rows = await db
|
||||
.select({
|
||||
id: groups.id,
|
||||
name: groups.name,
|
||||
oidcIss: groups.oidcIss,
|
||||
syncedAt: userGroups.syncedAt,
|
||||
})
|
||||
.from(userGroups)
|
||||
.innerJoin(groups, eq(userGroups.groupId, groups.id))
|
||||
.where(eq(userGroups.userId, userId))
|
||||
.orderBy(groups.name);
|
||||
|
||||
return (
|
||||
<Container className="pt-6 max-w-3xl">
|
||||
<PageHeader
|
||||
title="Groups"
|
||||
description="OIDC groups your identity provider asserted for you at last sign-in. Used by the upcoming sharing feature to decide which projects you can see."
|
||||
/>
|
||||
|
||||
{rows.length === 0 ? (
|
||||
<EmptyState
|
||||
title="No groups yet"
|
||||
description="Your IdP isn't emitting a `groups` claim on the access token, or you're not a member of any groups. See the troubleshooting section in the project README for how to configure Authentik / EntraID / Keycloak to emit group memberships."
|
||||
/>
|
||||
) : (
|
||||
<Card>
|
||||
{rows.map((g, i) => (
|
||||
<div
|
||||
key={g.id}
|
||||
className={`px-4 py-3 ${i > 0 ? "border-t border-border" : ""}`}
|
||||
>
|
||||
<div className="flex items-baseline gap-3">
|
||||
<div className="font-mono text-sm text-fg flex-1 truncate">
|
||||
{g.name}
|
||||
</div>
|
||||
<div className="text-xs text-fg-subtle whitespace-nowrap">
|
||||
synced {new Date(g.syncedAt).toLocaleString()}
|
||||
</div>
|
||||
</div>
|
||||
<div className="text-xs text-fg-subtle font-mono mt-0.5 truncate">
|
||||
{g.oidcIss}
|
||||
</div>
|
||||
</div>
|
||||
))}
|
||||
</Card>
|
||||
)}
|
||||
|
||||
<p className="text-xs text-fg-subtle mt-6">
|
||||
Groups refresh on every sign-in. If something looks stale,{" "}
|
||||
<Link href="/api/auth/signout">sign out</Link> and sign back in.
|
||||
</p>
|
||||
</Container>
|
||||
);
|
||||
}
|
||||
Reference in New Issue
Block a user